Dawn raids: ECJ clarifies rules for email seizures
On 16 July 2026, the Grand Chamber of the Court of Justice of the European Union (ECJ) delivered its judgment in Joined Cases C-258/23 to C-260/23 (IMI and Others v Autoridade da Concorrência). The judgment confirms that Articles 7 and 8 of the Charter of Fundamental Rights of the European Union (Charter) do not, in principle, preclude the seizure of business emails during inspections by competition law regulators at professional or business premises without prior authorisation by a court, provided that a strict legal framework and adequate safeguards, including full and effective ex post judicial review, are in place. It also requires prior independent review before investigators access data on mobile phones, computers or other storage media belonging to managers or employees, where appropriate after the device has been sealed.
A ‘dawn raid’ is an unannounced on-site inspection carried out by a competition authority investigating suspected infringements of the antitrust rules. Investigators arrive without advance warning, present a formal inspection decision or authorisation issued by the authority, and may examine and copy business records, including paper files, emails and other electronic data held on company systems. Digital evidence, particularly email, is now an important source of information in many inspections; that is the backdrop against which this judgment was delivered.
The case originated in three separate investigations by the Autoridade da Concorrência, the Portuguese competition authority (AdC), into suspected infringements of Articles 101 and 102 of the Treaty on the Functioning of the European Union (TFEU):
Between January 2021 and March 2022, the AdC carried out unannounced inspections at the premises of the companies concerned, authorised in advance by the Portuguese Public Prosecutor's Office. During those inspections, the AdC examined employees' emails and seized almost 13,000 computer files. The companies challenged the lawfulness of the inspections before the Tribunal da Concorrência, Regulação e Supervisão (the Portuguese Competition, Regulation and Supervision Court), which in turn referred three questions to the ECJ for a preliminary ruling.
In essence, the referring court asked:
The ECJ examined the second and third questions together, and assessed whether Articles 7 and 8 of the Charter preclude the seizure of business emails without prior authorisation issued by a court during an inspection at the professional or business premises of undertakings. The full text of the ECJ's judgment is available here.
The ECJ held that business emails exchanged between employees and managers by means of an undertaking’s messaging service constitute communications protected by Article 7 of the Charter. Article 7 guarantees everyone's right to respect for their private and family life, their home and their communications. Drawing on the case law of the European Court of Human Rights, the Grand Chamber confirmed that the same protection applies to communications sent from business premises as to communications sent from a private home. The protection does not depend on:
Nor is it relevant that a company has instructed staff not to use its email system for personal purposes: that internal rule governs permitted use of the system, but does not determine whether communications sent through it attract Charter protection. Drawing on WebMindLicenses (C-419/14), the ECJ confirmed that seizure of emails interferes with the right to respect for communications. Article 8 of the Charter is engaged in parallel because personal data relating to the traffic generated by business emails remains personal data, even in a professional context.
Having established that seizure of business emails interferes with the rights under Articles 7 and 8 of the Charter, the ECJ turned to whether that interference could be justified under Article 52(1) of the Charter.
That provision permits limitations on fundamental rights only where they are provided for by law, respect the essence of those rights and, subject to the principle of proportionality, are necessary and genuinely meet an objective of general interest recognised by the EU or the need to protect the rights and freedoms of others. Applying each of these four conditions in turn, the ECJ concluded that the seizure was justified:
The ECJ concluded that EU law does not require prior authorisation by a court or an independent administrative body for an inspection at business premises, including where emails are seized. Article 20(6) and (7) of Regulation (EC) No 1/2003 and Article 6(3) of Directive (EU) 2019/1 do not impose such a requirement; they leave it to Member States to decide whether to require prior authorisation under national law.
Where no prior court authorisation is obtained, the ECJ requires the national legal framework to provide:
National competition authorities must also comply with applicable EU data-protection law, including the GDPR, when processing the data they collect. This includes rules governing the purposes, retention and transfer of that data.
On the facts before it, the ECJ treated the Portuguese Public Prosecutor's Office as an independent authority capable of exercising prior oversight. Its authorisation contributed to the strict legal framework by defining the appropriateness, duration and material scope of the inspections and seizures. However, because that authorisation was not issued by a court, the ECJ stressed that data subjects must have access to full ex post judicial review meeting the requirements above.
The Grand Chamber drew a distinction for inspections involving mobile phones, computers or other storage media belonging to individual managers or employees rather than to the undertaking. Such devices may be used for both private and professional purposes. Access may reveal traffic and location data, photographs, browsing history, private communications and information about an individual’s daily habits, movements, relationships and social environment, potentially including special categories of personal data under Article 9 of the GDPR. The ECJ considered that this creates a risk of serious, or even particularly serious, interference with the rights protected by Articles 7 and 8 of the Charter.
Accordingly, where investigators need to access data on such a device, that access must, where appropriate after the device has been sealed, be subject to prior review by a court or an independent administrative body with all powers and guarantees necessary to strike a fair balance between the legitimate interests of the investigation and the individual's rights to privacy and data protection.
The judgment confirms that corporate email systems may be examined during an EU dawn raid even where no court has authorised the inspection in advance. Companies should focus on monitoring and recording the scope of the search, raising objections in real time where appropriate, and preserving their ability to seek full ex post judicial review.
The judgment draws a clear distinction between company-owned systems and devices belonging to individuals. Where a device belongs to an employee or manager, access to the data on it must, where appropriate after the device has been sealed, be subject to prior review by a court or an independent administrative body.
It remains ambiguous whether competition authorities can obtain advance blanket authorisation to access personal devices during a dawn raid or must instead wait until the specific devices have been seized or identified before seeking such permission. In our view, the ECJ's ruling means that where European Commission officials seek to access data on personal devices used for professional reasons during an inspection, such access must be subject to prior review by a court or an independent administrative authority. In the UK, the Competition and Markets Authority has the ability to require the production of copies of relevant information held on personal devices accessible from business premises under inspection, but a warrant is required to enter and search domestic premises, or to take a copy of a personal device away from any premises.
Companies should:
Ultimately, a company's response to a dawn raid is only as good as its preparation for one. Reception staff, IT personnel, and the designated response team should each know their role before an inspection ever begins, so that the company can cooperate fully with investigators while still preserving its ability to object to overreach in real time. Regular training and, where possible, simulated exercises remain the most reliable way of turning the principles set out in this judgment into a response that holds up in practice. Companies whose dawn raid protocols have not been reviewed recently may find it useful to consult our Dawn Raid Quickguide and ensure that our companion app, Ashurst Raid Assist, is available on the App Store and ready on the devices of those who would be first to greet inspectors.
Authors: Sergej Bräuer, Partner; Duncan Liddell, Partner; Chris Eberhardt, Partner; Dimitra Karakioulaki; Associate; Sarah Schaible, Transaction Lawyer and Aamir Hajjout, Research Assistant.
The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
Readers should take legal advice before applying it to specific issues or transactions.
Partner and Head of our London antitrust, regulatory and trade practice
London / Dublin